WordPress maintenance or security needs? Reach out!
TLDWP

Domain Security Report for k*l*u*q*a*t*e*-*r*u*t.de

Domain Information

WordPress Version: 7.1

Theme: ashe-pro-premium 3.8· 100% conf. (theme used by 1,934 domains)

Last Checked: 2026-09-09 19:27:39

HTTPS: Yes

Server: nginx

Response time (TTFB): 2,075 ms slow

Hosting: Keyweb AG (AS31103)

IP address: 84.19.176.xxx

Plugins (14)

Plugin Version Used By
complianz-gdpr 246,451
content-views-query-and-display-post-page 4.5.1.2· 85% conf. 26,447
download-manager 6.7.7· 60% conf. 19,964
eventon 5.0.13· 85% conf. 7,368
eventon-event-lists 895
eventonomy 1.6.0· 60% conf. 0
foobox-image-lightbox 2.8.5· 85% conf. 23,593
media-library-assistant 3.40· 85% conf. 77
ml-slider 3.112.0· 60% conf. 81,111
quform 4.3.0· 60% conf. 7,953
widget-options 4.2.5· 60% conf. 27,905
wp-show-posts 1.1.6· 60% conf. 16,999
wp-statistics 14.16.12· 60% conf. 54,670
wpdm-gutenberg-blocks 3.0.2· 60% conf. 804

Security Headers

F
Grade F

6 missing headers

Missing headers:

  • Strict-Transport-Security (HSTS) — Forces HTTPS connections ?
  • Content-Security-Policy (CSP) — Prevents XSS attacks ?
  • X-Content-Type-Options — Prevents MIME sniffing ?
  • X-Frame-Options — Prevents clickjacking ?
  • Referrer-Policy — Controls referrer information ?
  • Permissions-Policy — Limits browser features ?

Exposed Files & Configurations

This domain has publicly accessible security-sensitive files or configurations:

  • User enumeration exposed — Usernames are publicly discoverable via the REST API or author archives, aiding brute-force attacks ?

Need help securing your WordPress infrastructure? Contact us for a professional security audit.